CVE-2025-2127 | JoomlaUX JUX Real Estate 3.4.0 on Joomla realties Itemid/jp_yearbuilt cross site scripting
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties. The manipulation of the argument Itemid/jp_yearbuilt leads to cross site scripting.
This vulnerability is traded as CVE-2025-2127. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.